Security assessment method, device and equipment of receiving station and medium

By constructing a safety assessment map for LNG receiving terminals and utilizing fault tree, event tree, and bowtie models, combined with DEMATEL and ISM methods, the problems of inaccurate risk positioning and reliance on human experience in existing technologies were solved. This enabled rapid identification and accurate response to risk events, improving the systematic nature and timeliness of safety assessments.

CN121480950APending Publication Date: 2026-02-06PIPECHINA SOUTH CHINA CO +1
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202511616521.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-06
Publication Date
2026-02-06

AI Technical Summary

Technical Problem

Existing technologies for safety assessment of LNG receiving terminals suffer from limited data collection dimensions and incomplete coverage, resulting in insufficient accuracy in risk identification. Furthermore, the assessment process relies on human experience, leading to poor timeliness and difficulty in quickly identifying and responding to risk events.

Method used

By identifying risk events, safety indicators, and a comprehensive impact matrix, a safety assessment map is constructed to systematically identify risk causal relationships. Hazard sources are analyzed using fault tree, event tree, and bowtie models. Combined with DEMATEL and ISM methods, safety influencing factors are quantified, and a multi-level hierarchical structure model is generated.

Benefits of technology

It enables rapid location and precise response to risk events, improves the efficiency of risk investigation, enhances the accuracy of emergency decision-making and the preventive capabilities of safe operations, and guides safety design and operation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121480950A_ABST
    Figure CN121480950A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a safety assessment method and device for a receiving station, equipment and a medium, and the method comprises the steps: determining a risk event according to a hazard source in a to-be-assessed receiving station, and enabling the risk event to represent a hazard source out-of-control event; determining a safety index of the to-be-evaluated receiving station according to historical data associated with the risk event of other receiving stations and the technological process of the to-be-evaluated receiving station; a comprehensive influence matrix is determined according to the index scores of the safety indexes, a safety evaluation graph of the to-be-evaluated receiving station is determined based on the comprehensive influence matrix, and the safety evaluation graph is used for investigation operation of risk events of the receiving station and characterization of the causal relationship and the hierarchy of the safety indexes. Based on the safety assessment diagram provided by the embodiment of the invention, accident cause factors, causal relationships and levels can be determined, the accuracy of risk disposal can be improved, and meanwhile, through the safety indexes and the safety assessment diagram, the accident occurrence mechanism can be known, the accident prevention capability can be improved, and the occurrence of accidents can be avoided.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of safety engineering, and in particular to a safety evaluation method, device and equipment of a receiving station and a medium. BACKGROUND

[0002] The LNG (Liquefied Natural Gas) receiving station is the core hub for the storage and transportation of liquefied natural gas. Its operation process involves high-risk scenarios such as low temperature, high pressure, flammable and explosive, and safety is the lifeline. Due to the complex process flow and strong correlation between the devices in the system, potential hidden dangers in any link may trigger a chain of risk accidents. Therefore, systematic safety evaluation should be carried out before operation.

[0003] However, although the existing safety evaluation technology can identify some hidden dangers, it still has obvious limitations in practical application. On the one hand, the data collection dimension is single and not comprehensive, resulting in insufficient accuracy of risk positioning; on the other hand, the evaluation process relies too much on human experience and the subjectivity of judgment is strong, and the timeliness of risk response is poor. In the event of a sudden risk event, it is difficult to achieve rapid and accurate cause identification and response. SUMMARY

[0004] The present application provides a safety evaluation method, device and equipment of a receiving station and a medium. Through the safety evaluation diagram of the technical solution of the present application embodiment, the cause of the risk occurrence can be accurately determined, the efficiency of risk investigation is improved, and the safety of the receiving station is ensured. Through the safety index and the safety evaluation diagram, the interaction mechanism of the cause factors of the risk event can be understood, and then the risk occurrence can be prevented, and the safety design and safety operation can be guided.

[0005] The present application embodiment provides a safety evaluation method of a receiving station, comprising:

[0006] According to the risk source in the receiving station to be evaluated, a risk event is determined, wherein the risk event represents a dangerous source out-of-control event;

[0007] According to the historical data of other receiving stations associated with the risk event and the process flow of the receiving station to be evaluated, safety indexes of the receiving station to be evaluated are determined;

[0008] According to the index score of each safety index, a comprehensive influence matrix is determined, and a safety evaluation diagram of the receiving station to be evaluated is determined based on the comprehensive influence matrix, wherein the safety evaluation diagram is used for the investigation operation of the risk event of the receiving station to be evaluated, and represents the causal relationship and hierarchy of each safety index.

[0009] In a second aspect, the present application embodiment provides a safety evaluation device of a receiving station, comprising:

[0010] The risk event determination module is used to determine risk events based on the hazards within the receiving station to be evaluated, wherein the risk event characterizes an event of hazard source loss of control;

[0011] The safety indicator determination module is used to determine the safety indicators of the receiving station to be evaluated based on historical data of other receiving stations associated with the risk event and the process flow of the receiving station to be evaluated.

[0012] The generation module is used to determine a comprehensive impact matrix based on the index scores of each security indicator, and to determine a security assessment map of the receiving station to be evaluated based on the comprehensive impact matrix. The security assessment map is used to perform risk event investigation operations on the receiving station to be evaluated, and to characterize the causal relationship and hierarchy of each security indicator.

[0013] Thirdly, embodiments of the present invention provide an electronic device, the electronic device comprising:

[0014] At least one processor; and,

[0015] A memory communicatively connected to the at least one processor; wherein,

[0016] The memory stores a computer program that can be executed by the at least one processor, which enables the at least one processor to perform the security assessment method for the receiving station as described in any one of the embodiments of the present invention.

[0017] Fourthly, embodiments of the present invention provide a computer-readable storage medium storing computer instructions, which are used to cause a processor to execute the security assessment method for a receiving station as described in any one of the embodiments of the present invention.

[0018] This invention provides a method, apparatus, equipment, and medium for safety assessment of a receiving station. The method includes: identifying risk events based on hazards within the receiving station to be assessed, wherein the risk events characterize uncontrolled hazard events; determining safety indicators for the receiving station to be assessed based on historical data of other receiving stations related to the risk events and the process flow of the receiving station to be assessed; determining a comprehensive influence matrix based on the score of each safety indicator; and determining a safety assessment diagram for the receiving station to be assessed based on the comprehensive influence matrix. The safety assessment diagram is used to investigate the risk events at the receiving station to be assessed, characterizing the causal relationship and hierarchy of each safety indicator. Specifically, a comprehensive influence matrix is ​​constructed using the score results of each safety indicator, and a safety assessment diagram for the receiving station to be assessed is generated based on the comprehensive influence matrix. When a risk event occurs, the safety assessment diagram can be used to quickly locate the cause of the risk, thereby improving the accuracy and efficiency of emergency decision-making and effectively ensuring operational safety. Simultaneously, the interaction mechanism of the causative factors of the risk event can be understood through the safety indicators and the safety assessment diagram, thereby preventing the occurrence of risks and guiding safety design and safe operation. Attached Figure Description

[0019] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0020] Figure 1 A flowchart of a security assessment method for a receiving station is provided in Embodiment 1 of the present invention;

[0021] Figure 2 This is a schematic diagram of a bow-shaped model of a liquefied natural gas leak at a receiving station, provided in an embodiment of the present invention.

[0022] Figure 3 A schematic diagram of a bow-shaped model of evaporative gas leakage at a receiving station provided in an embodiment of the present invention;

[0023] Figure 4 A flowchart of a security assessment method for a receiving station provided in Embodiment 2 of the present invention;

[0024] Figure 5 A schematic diagram of a safety assessment diagram provided in an embodiment of the present invention;

[0025] Figure 6 This is a schematic diagram of the structure of a security assessment device for a receiving station provided in Embodiment 3 of the present invention;

[0026] Figure 7This is a schematic diagram of the structure of an electronic device provided in Embodiment 4 of the present invention. Detailed Implementation

[0027] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.

[0028] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0029] It should be noted that the collection, storage, use, processing, transmission, provision, and disclosure of user personal information involved in the technical solution disclosed herein all comply with the provisions of relevant laws and regulations and do not violate public order and good morals.

[0030] Example 1

[0031] Figure 1 This invention provides a flowchart of a security assessment method for a receiving station according to Embodiment 1. This method is specifically applicable to generating a security assessment map of the receiving station, and then assessing and tracing risk events based on the security assessment map. This method can be executed by a security assessment device for the receiving station, which can be composed of software and / or hardware and configured in a computer or server.

[0032] like Figure 1 As shown, it includes:

[0033] Step 110: Based on the hazards within the receiving station to be evaluated, determine the risk events, wherein the risk events characterize events where the hazards are out of control.

[0034] Among them, liquefied natural gas (LNG) receiving terminals, which are the subjects of safety risk assessments, consist of various process systems, storage facilities, and supporting engineering projects. Hazardous sources refer to fuels or hazardous chemicals within the receiving terminal that may be released uncontrollably. Risk events are specific safety accidents that result in personal injury, equipment damage, or environmental destruction due to leaks, spontaneous combustion, or other abnormal releases triggered by hazardous sources.

[0035] Specifically, due to the complexity of the equipment environment and processes within the receiving station, a risk assessment needs to be conducted before operation to generate a corresponding safety assessment diagram. In the event of a risk, the cause of the risk can be quickly determined based on the safety assessment diagram.

[0036] Step 120: Determine the safety indicators of the receiving station to be evaluated based on historical data of other receiving stations related to the risk event and the process flow of the receiving station to be evaluated.

[0037] Other receiving terminals are facilities of the same type as the terminal under evaluation (e.g., LNG receiving terminals), that have completed safety assessments, or have accumulated risk event data from historical operations. The process flow represents the operational logic and constraints between various production units, equipment systems, and control links at the terminal under evaluation under normal operating conditions. Safety indicators characterize the potential causes of risk events at the terminal under evaluation, such as risky operations performed by personnel or equipment.

[0038] Specifically, historical data on risk events from other receiving stations can provide common risk references, while the process flow of the receiving station to be evaluated can reflect its own operational characteristics. Combining these two aspects ensures that safety indicators accurately reflect the actual production and operation of the receiving station under evaluation. Furthermore, by understanding the causal relationships between safety indicators, managers can quickly identify critical points and formulate precise, multi-node coordinated intervention strategies, thereby systematically improving accident prevention capabilities and emergency decision-making efficiency, and guiding the optimization of the risk control system, the improvement of safety regulations, and the allocation of emergency management resources.

[0039] Optionally, step 120 includes:

[0040] Based on the historical data and the process flow, fault tree analysis is used to identify the causes and preventive barriers of the risk events, and event tree analysis is used to identify the consequences and mitigation barriers of the risk events.

[0041] Based on the causes, prevention barriers, consequences, and mitigation barriers of the risk event, determine the bowtie model corresponding to the risk event;

[0042] The safety indicators are determined based on the bow model.

[0043] Fault tree analysis is a logical deductive method that starts from a risk event and traces back to the direct and indirect causes (such as equipment failure, human error, etc.) leading to the event, and is used to systematically identify risk causal chains. For example, if the risk event is "LNG leakage", the causal chain of "human misoperation → pipeline valve malfunction → LNG leakage" can be deduced, clearly showing the accident triggering path.

[0044] Event tree analysis, in particular, starts with a risk event and works forward to deduce its development path and potential consequences. For example, if the risk event is "LNG leakage," a logical chain of "LNG leakage → fire / explosion → environmental damage" can be derived. By analyzing this chain, the scope of the risk event and the severity of its consequences can be assessed.

[0045] The bowtie model centers on risk events, integrating the causes and preventative barrier relationships from fault tree analysis on the left, and the consequences and mitigation barriers from event tree analysis on the right, forming a bowtie-like relationship diagram. Preventative and mitigation barriers represent defensive measures to prevent risk events from occurring and reactive measures to mitigate their occurrence, respectively.

[0046] Specifically, based on the failure modes of risk causes, prevention barriers, and mitigation barriers in the bow tie model, and combined with historical data of risk events, feature classification analysis is carried out to identify key causes and key impacts affecting the evolution path of risk events, and finally, safety indicators are extracted.

[0047] Furthermore, this embodiment of the invention identifies complex accident scenarios (LNG receiving terminal scenarios), summarizes and analyzes historical accident causal paths, combines dual prevention and mitigation logic, fully reconstructs the accident evolution path, extracts key links in risk management, integrates key safety influencing factors, and uses these key safety influencing factors as safety indicators to guide the actual operation of the receiving terminal and prevent risk events from occurring.

[0048] For example, Figure 2 This is a schematic diagram of a bow-shaped model of liquefied natural gas leakage at a receiving station, provided in an embodiment of the present invention. Figure 3 This is a schematic diagram of a bow-shaped model of evaporative gas leakage at a receiving station, provided in an embodiment of the present invention. Figure 2 The center's risk events involve LNG leakage into the external environment, which generally consist of four parts: the cause of the leak, preventative barriers, mitigation barriers, and consequences. Causes include pipeline corrosion and operational errors; preventative barriers include regular inspections and explosion-proof equipment; mitigation barriers involve controlling ignition sources and gas detection systems; consequences may include fire, explosion, and personal injury. Figure 3The center's risk events are BOG (Boil-off Gas) leaks to the site, generally consisting of four parts: the cause of the leak, preventative barriers, mitigation barriers, and consequences. Causes include pipeline corrosion in the tank area, operational errors, and equipment failure and seal failure in the compressor plant. Preventative barriers include explosion-proof electrical systems, safety valves, and BOG compressors. Mitigation barriers involve gas detection systems, fire alarm systems, and active fire suppression systems. Consequences may include fire, explosion, and personal injury. Specifically, based on the bow-tie model of LNG and BOG leaks, considering the causes, preventative barriers, and mitigation barrier failure scenarios, combined with LNG receiving terminal accident statistical analysis and on-site investigations, a systematic analysis of the accident's causal path and consequence evolution mechanism can be conducted to screen key safety influencing factors and formulate corresponding safety indicators for the risk events.

[0049] Optionally, the safety indicators include: factors influencing the risk events from the perspectives of personnel, equipment, environment, and safety management.

[0050] For example:

[0051] The personnel dimension represents individual qualities and human error, specifically including: personnel misoperation; personnel violation of operating procedures; and personnel failure to respond in a timely manner.

[0052] The equipment dimension characterizes the reliability and safety of equipment, specifically including: pipeline corrosion and other defects, BOG (Boil-Off Gas) compression, booster unit failure, storage tank and its auxiliary equipment failure, DCS (Distributed Control System), SIS (Safety Instrumented System) imbalance, GDS (Gas Detection System), FAS (Fire Alarm System) failure, system failure, and fire protection facility failure.

[0053] Environmental factors characterize the hazards present in the environment, including: the presence of ignition sources, the presence of combustibles, site settlement, and on-site handling conditions.

[0054] The safety management dimension characterizes the deficiencies in safety management, including: deficiencies in emergency plans, insufficient investment in safety production, inadequate implementation of safety management, and imperfect safety management systems.

[0055] Step 130: Determine the comprehensive impact matrix based on the index scores of each security indicator, and determine the security assessment map of the receiving station to be evaluated based on the comprehensive impact matrix. The security assessment map is used to investigate the risk events of the receiving station to be evaluated and to characterize the causal relationship and hierarchy of each security indicator.

[0056] The safety indicator score represents the correlation between two safety indicators. This score can be determined manually by multiple domain experts or through statistical analysis of historical data. The specific method is not limited here. The comprehensive influence matrix includes the cumulative correlation between any safety indicator and other safety indicators, such as those with direct and indirect influences on the stated safety indicator. The safety assessment diagram is used to investigate risk events at the receiving station to be assessed, representing the causal relationships and hierarchy of each safety indicator. The causal relationship can be determined by the connection of arrows in the diagram, and the hierarchy of the safety indicators can be determined by their position in the safety assessment diagram.

[0057] Specifically, an ISM (Interpretative Structural Modeling Method) analysis can be performed on the comprehensive impact matrix to determine the safety assessment map of the receiving station to be evaluated. Furthermore, when an accident occurs, the specific manifestations of the accident can be used to query the safety assessment map, thereby identifying the multi-level causes of the accident, enabling rapid cause localization and accident handling. Simultaneously, safety indicators and the safety assessment map can be used to understand the interaction mechanism of causative factors of risk events, thereby preventing risks and guiding safety design and operation. Furthermore, the beneficial effects of this invention embodiment may include:

[0058] Multi-model system integration to build a complete assessment chain: By integrating three model systems—Bow-tie, DEMATEL (Decision-Making Trial and Evaluation Laboratory) and ISM—a complete risk assessment system has been built, from accident scenario construction and factor quantitative analysis to hierarchical structure division. This effectively overcomes the limitations of existing LNG receiving terminal risk assessment methods in terms of systematicness, hierarchy, and quantitative capabilities.

[0059] The accident scenario is visualized with a clear path to cause: Based on the Bow-tie model, the complete evolution path of an accident from cause to consequence is displayed intuitively, and preventive and mitigating safety barriers and their failure modes are clearly identified. This allows for the accurate extraction of key control points, the construction of a scientific system of accident influencing factors, and a reduction in reliance on subjective experience.

[0060] Factor quantification and hierarchical structure visualization: The DEMATEL-ISM method is used to quantify the causal relationships and importance among various safety influencing factors, construct a multi-level hierarchical structure model, and intuitively present the complex action paths and hierarchical relationships among factors. This realizes the transformation from single-point hidden danger investigation to the identification of critical paths of accident evolution, and improves the systematicness and pertinence of risk management.

[0061] The assessment results are objective and provide strong decision support: effectively supporting safety risk assessment and prevention decisions throughout the entire lifecycle of an LNG receiving terminal, providing a reliable basis for the precision and foresight of complex system safety management. Specifically, this method can also intervene in the early stages of a project (design phase), determining the terminal's process flow based on the terminal's design drawings. Therefore, this invention, from an inherent safety perspective, determines the risk importance of safety influencing factors and the multi-level progressive logic of accident occurrence through the correlation logic and constraints of various safety influencing factors (safety indicators) of the receiving terminal, thereby guiding the safety design and operation of the receiving terminal. Furthermore, safety professionals should place more emphasis on prevention. This method aims to enable managers to quickly identify key nodes, formulate precise multi-node collaborative blocking strategies, thereby systematically improving accident prevention capabilities and emergency decision-making efficiency, guiding the optimization of risk control systems, the improvement of safety regulations, and the allocation of emergency management resources.

[0062] This invention provides a safety assessment method for a receiving station. The method includes: identifying risk events based on hazards within the receiving station to be assessed, wherein the risk events characterize uncontrolled hazard events; determining safety indicators for the receiving station to be assessed based on historical data of other receiving stations related to the risk events and the process flow of the receiving station to be assessed; determining a comprehensive impact matrix based on the index scores of each safety indicator; and determining a safety assessment map for the receiving station to be assessed based on the comprehensive impact matrix. The safety assessment map is used to investigate the risk events at the receiving station to be assessed, characterizing the causal relationships and levels of each safety indicator. Specifically, the comprehensive impact matrix is ​​determined by the index scores of each safety indicator, and the safety assessment map for the receiving station to be assessed is determined based on the comprehensive impact matrix. When a risk event occurs, the safety assessment map can quickly locate the cause of the risk, thereby improving the accuracy of decision-making and response efficiency, ensuring safety. Furthermore, through safety indicators and the safety assessment map, the occurrence mechanism of risk events can be understood, thereby preventing risks and guiding safety design and operation.

[0063] Example 2

[0064] Figure 4 This is a flowchart of a security assessment method for a receiving station provided in Embodiment 2 of the present invention. The method specifically defines a method for determining a comprehensive influence matrix based on the index scores of each security indicator, and determining a security assessment map of the receiving station to be assessed based on the comprehensive influence matrix.

[0065] like Figure 4 As shown, it includes:

[0066] Step 210: Based on the hazards within the receiving station to be evaluated, determine the risk events, wherein the risk events characterize events where the hazards are out of control.

[0067] Step 220: Determine the safety indicators of the receiving station to be evaluated based on historical data of other receiving stations related to the risk event and the process flow of the receiving station to be evaluated.

[0068] Step 230: Determine the direct impact matrix based on the index scores of the safety indicators, normalize the direct impact matrix, and determine the normalized impact matrix.

[0069] Specifically, the direct impact matrix includes the correlation between any two security indicators. Normalization can be a method of standardization and unification, used to unify the elements in the direct impact matrix to the same numerical range.

[0070] Alternatively, the matrix B that directly affects can be determined by the following formula:

[0071] ;

[0072] in, The direct influence of safety indicator i given by the k-th expert on safety indicator j is given by m, where m is the number of experts. The number of rows and columns of the direct influence matrix B represents the total number of safety indicators. The x-row and y-column matrix represents the correlation between the safety indicators in row x and column y.

[0073] Furthermore, the normalized influence matrix C can be determined using the following formula:

[0074] ;

[0075] in, This represents the row sum and maximum value that directly affect matrix B.

[0076] Step 240: Perform multi-power matrix self-multiplication on the normalized influence matrix to obtain multiple candidate influence matrices, and determine the comprehensive influence matrix based on each candidate influence matrix.

[0077] Specifically, the comprehensive influence matrix T can be determined using the following formula:

[0078] ;

[0079] in, The candidate influence matrix is ​​determined by multiplying the normalized influence matrix C by a power of n.

[0080] Optional, when n approaches infinity It tends towards 0, so it can be approximated by the following formula: In the formula, I is the identity matrix.

[0081] Specifically, the direct impact matrix / normalized impact matrix only considers the direct pairwise influence between accident safety indicators, without considering indirect influences and ripple effects. The comprehensive impact matrix represents the sum of the direct and indirect influences of each safety indicator, which can determine the final impact of each safety indicator on the accident.

[0082] Step 250: Determine the security assessment map of the receiving station to be evaluated based on the comprehensive influence matrix.

[0083] Specifically, step 250 includes:

[0084] Based on the comprehensive influence matrix, the identity matrix, and the preset influence threshold, an reachability matrix is ​​determined, wherein the reachability matrix represents the reachability relationship between various security indicators.

[0085] Specifically, the comprehensive influence matrix T can be added to the identity matrix I to obtain the overall influence matrix. Then, the reachability matrix is ​​determined using the overall influence matrix and a preset influence threshold. The preset influence threshold filters elements in the overall influence matrix with excessively low influence values. If an element's value is below the preset influence threshold, it is set to 0; otherwise, it is set to 1, thus obtaining the reachability matrix. Furthermore, if the element in row X and column Y of the reachability matrix is ​​1, it indicates that the reachability relationship between the safety indicator corresponding to row X and the safety indicator corresponding to row Y is that X can reach Y. Further, X can reach Y signifies that during an accident, safety indicator X directly affects the occurrence of safety indicator Y. For example, if safety indicator X is pipeline damage, then Y could be the presence of flammable materials. That is, X can reach Y can be understood as the presence of flammable materials in the environment due to pipeline damage and LNG leakage.

[0086] Furthermore, each row of the overall impact matrix corresponds to a security indicator, and the row of the security indicator includes each first target security indicator that can be reached by the security indicator. Each column also corresponds to a security indicator, and the column of the security indicator includes each second target security indicator that can be reached by the security indicator.

[0087] Based on the reachability matrix, the influence level of each security indicator on the occurrence of risk events and the logical path of risk events are determined. The influence level represents the degree of influence of security indicators on the occurrence of risk events, and the logical path represents the association structure of security indicators.

[0088] The influence level characterizes the degree of impact of safety indicators on the occurrence of risk events. Safety indicators with higher influence levels are closer to the essential cause (root cause) of the accident; safety indicators with lower influence levels are closer to the immediate cause (direct cause). The logical path characterizes the correlation structure of safety indicators. Specifically, it can be the path from the essential cause to the immediate cause during the accident's occurrence, with each point on the path representing a safety indicator at its respective influence level. In other words, the correlation structure of safety indicators represents the causal relationship between safety indicators during the accident's occurrence.

[0089] Optionally, based on the reachability matrix, determine the impact level of each security indicator on the occurrence of risk events, as well as the logical path of the risk events, including:

[0090] Based on the reachability relationships between security indicators in the reachability matrix, a first indicator set and a second indicator set for each security indicator are determined. The first indicator set includes security indicators reachable along the column dimension, and the second indicator set includes security indicators reachable along the row dimension. The union of the first and second indicator sets is deleted from the reachability matrix to obtain a new reachability matrix. The process then returns to the previous step, resuming the determination of the first and second indicator sets based on the reachability relationships between security indicators in the reachability matrix. If the new reachability matrix is ​​empty, the influence level of each security indicator is determined according to the order of deletion of the union. Finally, the logical path of the risk event is determined based on the reachability relationships between the security indicators in the reachability matrix.

[0091] In this context, the first indicator in the first set of safety indicators is accessible to the stated safety indicator. The safety indicator is accessible to the second indicator in the second set of safety indicators. Let A be a safety indicator, B be the first indicator, and C be the second indicator. Then, B->A, A->C. The arrows indicate reachability relationships.

[0092] Furthermore, if Then delete the row and column corresponding to security index i in the reachability matrix, where R i S is the second set of indicators for safety indicator i. iLet be the first set of safety indicators I. The mathematical meaning of this condition is: if the union of the second set of safety indicator i and its first set equals its own second set, it indicates that the influence of the safety indicator has been completely covered by the safety indicators in the first set and can be eliminated. After deletion, a new reachability matrix is ​​obtained. Subsequently, based on this new reachability matrix, the first and second sets of the remaining safety indicators need to be recalculated, and the union calculation is performed again. Rows and columns of safety indicators whose union satisfies the above formula are deleted from the current reachability matrix. This iterative operation is repeated until all rows and columns corresponding to all safety indicators are deleted. Furthermore, the deletion order of each safety indicator corresponds to its influence level: the earlier the deletion, the lower the influence level, and the closer to the direct cause of the accident; the later the deletion, the higher the influence level, and the closer to the root cause of the accident.

[0093] The security assessment diagram of the receiving station to be evaluated is determined based on the impact level of each security indicator and the logical path of the risk event.

[0094] Specifically, security indicators at each security level can be connected based on the logical path of risk events to obtain a security assessment diagram.

[0095] For example, Figure 5 A schematic diagram of a safety assessment diagram provided in an embodiment of the present invention is shown in the figure, F1-F 17 These are safety indicators, and L1-L8 represent the impact levels, with L1 being the highest impact level and representing the immediate cause (direct cause) of the accident, and L8 being the lowest impact level and representing the essential cause (root cause) of the accident. Figure 5 The arrows between the safety indicators indicate the reachability relationships between them, such as F. 17 →F 15 This indicates that F 17 The result can reach F 15 F 17 The occurrence of F 15 The occurrence of this. Furthermore, F 10 (Ignition source present), F 11 (Flammable material is present) F 13 (On-site handling conditions). Surface safety indicators are significantly affected by deeper or root-cause safety indicators. Taking measures to directly control these risk factors can effectively prevent accidents from occurring. Levels L2-L6 are transitional causative factors, influenced by lower-level factors while also affecting upper-level safety indicators. These include F6 (tank and auxiliary equipment failure), F9 (fire protection facility failure), F4 (pipeline corrosion and other defects), F5 (BOG compressor and booster unit failure), and F... 12(Work site settlement), F3 (personnel failure to respond in a timely manner), F7 (DCS system and SIS system imbalance), F8 (GDS system and FAS system failure), F 14 (Emergency plan deficiencies). These factors do not directly cause accidents, but their complex interactions will reduce system safety performance, making the system prone to accidents. L7-L8 are the essential causal factors, including F1 (personnel misoperation), F2 (personnel violation of operating procedures), and F... 15 (Insufficient investment in safety production), F 16 (Inadequate implementation of safety management), F 17 (Inadequate safety management system). These factors are independent, and taking protective measures may not yield immediate and obvious feedback, but they can fundamentally reduce the potential risk of accidents.

[0096] Optionally, based on the comprehensive influence matrix, the influence degree, affected degree, causal degree, and centrality of each safety indicator are determined;

[0097] The impact, affectedness, causation, and centrality of each safety indicator are marked on the safety assessment diagram.

[0098] Specifically, the impact, affectedness, causation, and centrality of each safety indicator can be determined using the following formulas:

[0099] ;

[0100] ;

[0101] ;

[0102] .

[0103] Influence f i This represents the sum of the direct and indirect impacts of a safety indicator on all other safety indicators; the degree of influence e. j The centrality F represents the degree to which a safety indicator is influenced by the combined effects of all other safety indicators. i Used to measure the importance and activity of security indicators in the system; the higher the value, the more critical the security indicator. (Causality G) i It reflects the net impact of a safety indicator on other safety indicators. A positive value indicates that it has a significant impact on other safety indicators, while a negative value indicates that the safety indicator is easily affected by other safety indicators.

[0104] Furthermore, the impact, affectedness, causation, and centrality of each safety indicator can be marked on the safety assessment diagram. This allows for a faster determination of the impact of each safety indicator on the accident when a safety incident occurs, improving the accuracy of accident cause determination and increasing the efficiency of accident handling.

[0105] Figure 6 This diagram illustrates a safety assessment method for LNG receiving terminals provided by an embodiment of the present invention. Specifically, the system identifies hazardous sources within the LNG receiving terminal, designates uncontrolled hazardous source events as top events, and comprehensively utilizes Fault Tree Analysis (FTA) and Event Tree Analysis (ETA) methods to fully analyze the causes and consequences of uncontrolled hazardous sources, identify corresponding prevention and mitigation barriers, and ultimately form a complete Bow-tie model. Based on this, the safety influencing factors of the LNG receiving terminal are summarized and categorized. Using the DEMATEL method, matrix theory and graph theory principles are applied to standardize the influencing factors, achieving a quantitative assessment of the degree of influence of accident causative factors, resulting in a comprehensive influence matrix for risk events. Based on the comprehensive influence matrix, ISM method analysis can be performed to obtain a multi-level hierarchical structure diagram (safety assessment diagram). Simultaneously, the influence degree, affected degree, centrality, and causal degree of safety indicators can be determined based on the comprehensive influence matrix. The method of this embodiment of the invention can quickly determine the impact of each safety indicator on an accident, improve the accuracy of accident cause determination, and thus improve the efficiency of accident handling after an accident occurs.

[0106] This invention provides a security assessment method for receiving stations. Specifically, by stratifying various security indicators and determining the logical paths of risk events, the mechanism of an accident can be more clearly defined, and the impact of security indicators on the accident can be more accurately characterized. Therefore, when a risk event occurs, the cause of the risk can be quickly located through a security assessment diagram, thereby improving the accuracy of decision-making and response efficiency, ensuring safety. Through security indicators and security assessment diagrams, the mechanism of risk events can be understood, thereby preventing risks from occurring and guiding safety design and operation.

[0107] Example 3

[0108] Figure 6 This is a schematic diagram of the structure of a security assessment device for a receiving station provided in Embodiment 3 of the present invention. Figure 6 As shown, the device includes:

[0109] The risk event determination module 310 is used to determine risk events based on the hazards within the receiving station to be evaluated, wherein the risk event characterizes an event of hazard source loss of control.

[0110] The safety indicator determination module 320 is used to determine the safety indicators of the receiving station to be evaluated based on historical data of other receiving stations associated with the risk event and the process flow of the receiving station to be evaluated.

[0111] The generation module 330 is used to determine a comprehensive impact matrix based on the index scores of each security indicator, and to determine a security assessment map of the receiving station to be evaluated based on the comprehensive impact matrix. The security assessment map is used to perform the risk event investigation operation on the receiving station to be evaluated, and to characterize the causal relationship and hierarchy of each security indicator.

[0112] This invention provides a safety assessment device for a receiving station. The device involves: identifying risk events based on hazards within the receiving station to be assessed, where each risk event represents a hazard source out of control event; determining safety indicators for the receiving station to be assessed based on historical data of other receiving stations related to the risk events and the process flow of the receiving station to be assessed; determining a comprehensive influence matrix based on the scores of each safety indicator; and generating a safety assessment map for the receiving station to be assessed based on the comprehensive influence matrix. The safety assessment map is used to investigate the risk events at the receiving station to be assessed, representing the causal relationships and hierarchy of each safety indicator. Specifically, a comprehensive influence matrix is ​​constructed using the scores of each safety indicator, and a safety assessment map for the receiving station to be assessed is generated based on the comprehensive influence matrix. When a risk event occurs, the safety assessment map can be used to quickly locate the cause of the risk, thereby improving the accuracy and efficiency of emergency decision-making and effectively ensuring operational safety. Through safety indicators and the safety assessment map, the mechanism of risk event occurrence can be understood, thereby preventing risks and guiding safety design and safe operation.

[0113] Optionally, the safety indicator determination module 320 includes:

[0114] The analysis unit is used to identify the causes and preventive barriers of the risk events through fault tree analysis, and to identify the consequences and mitigation barriers of the risk events through event tree analysis, based on the historical data and the process flow.

[0115] The model generation unit is used to determine the bowtie model corresponding to the risk event based on the cause, prevention barrier, consequence and mitigation barrier of the risk event;

[0116] The indicator determination unit is used to determine the safety indicator based on the bow model.

[0117] The safety indicators include the influencing factors that lead to the risk events from the perspectives of personnel, equipment, environment, and safety management.

[0118] Optionally, the generation module 330 includes:

[0119] The normalized impact matrix determination unit is used to determine the direct impact matrix based on the index scores of the safety indicators, normalize the direct impact matrix, and determine the normalized impact matrix.

[0120] The comprehensive influence matrix determination unit is used to perform multi-power matrix self-multiplication on the normalized influence matrix to obtain multiple candidate influence matrices, and determine the comprehensive influence matrix based on each candidate influence matrix;

[0121] The security assessment map determination unit is used to determine the security assessment map of the receiving station to be assessed based on the comprehensive influence matrix.

[0122] Optionally, the safety assessment diagram determination unit includes:

[0123] The reachability matrix determination unit is used to determine the reachability matrix based on the comprehensive influence matrix, the identity matrix and the preset influence threshold, wherein the reachability matrix represents the reachability relationship between various security indicators;

[0124] The analysis unit is used to determine the level of influence of each security indicator on the occurrence of risk events, as well as the logical path of risk events, based on the reachability matrix. The level of influence represents the degree of influence of security indicators on the occurrence of risk events, and the logical path represents the association structure of security indicators.

[0125] The generation unit is used to determine the security assessment diagram of the receiving station to be evaluated based on the impact level of each security indicator and the logical path of the risk event.

[0126] Optionally, the analysis unit includes:

[0127] The indicator set determination subunit is used to determine the first indicator set and the second indicator set of each security indicator based on the reachability relationship between each security indicator in the reachability matrix. The first indicator set includes security indicators that have reachability relationships in the column dimension, and the second indicator set includes security indicators that have reachability relationships in the row dimension.

[0128] The loop subunit is used to delete the union of the first indicator set and the second indicator set from the reachability matrix to obtain a new reachability matrix, and then return to execute the determination of the first indicator set and the second indicator set of each security indicator based on the reachability relationship between each security indicator in the reachability matrix.

[0129] The judgment sub-unit is used to determine the impact level of each security indicator based on the deletion order of the intersection if the new reachability matrix is ​​an empty set;

[0130] A sub-unit is generated to determine the logical path of the risk event based on the reachability relationships between the security indicators in the reachability matrix.

[0131] Optionally, the security assessment device for the receiving station also includes:

[0132] The calculation unit is used to determine the influence degree, affected degree, causal degree and centrality of each safety indicator based on the comprehensive influence matrix.

[0133] The annotation unit is used to annotate the influence, affectedness, causation and centrality of each safety indicator in the safety assessment diagram.

[0134] The security assessment device for receiving stations provided in this embodiment of the invention can execute the security assessment method for receiving stations provided in any embodiment of the invention, and has the corresponding functional modules and beneficial effects for executing the method.

[0135] Example 4

[0136] Figure 7 A schematic diagram of an electronic device 10, which can be used to implement embodiments of the present invention, is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (e.g., helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.

[0137] like Figure 7 As shown, the electronic device 10 includes at least one processor 11 and a memory, such as a read-only memory (ROM) 12 or a random access memory (RAM) 13, communicatively connected to the at least one processor 11. The memory stores computer programs executable by the at least one processor. The processor 11 can perform various appropriate actions and processes based on the computer program stored in the ROM 12 or loaded from storage unit 18 into the RAM 13. The RAM 13 can also store various programs and data required for the operation of the electronic device 10. The processor 11, ROM 12, and RAM 13 are interconnected via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.

[0138] Multiple components in electronic device 10 are connected to I / O interface 15, including: input unit 16, such as keyboard, mouse, etc.; output unit 17, such as various types of displays, speakers, etc.; storage unit 18, such as disk, optical disk, etc.; and communication unit 19, such as network card, modem, wireless transceiver, etc. Communication unit 19 allows electronic device 10 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.

[0139] Processor 11 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Processor 11 performs the various methods and processes described above, such as the security assessment methods for a receiving station.

[0140] In some embodiments, the security assessment method for the receiving station may be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed on the electronic device 10 via ROM 12 and / or communication unit 19. When the computer program is loaded into RAM 13 and executed by processor 11, one or more steps of the security assessment method for the receiving station described above may be performed. Alternatively, in other embodiments, processor 11 may be configured to perform the security assessment method for the receiving station by any other suitable means (e.g., by means of firmware).

[0141] Various implementations of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various implementations may include: implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.

[0142] Computer programs used to implement the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be performed. The computer programs may be executed entirely on a machine, partially on a machine, or as a standalone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.

[0143] In the context of this invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.

[0144] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).

[0145] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or middleware components (e.g., application servers), or frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.

[0146] A computing system can include clients and servers. Clients and servers are generally located far apart and typically interact through communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a hosting product within the cloud computing service system to address the shortcomings of traditional physical hosts and VPS services, such as high management difficulty and weak business scalability.

[0147] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this invention can be achieved, and this is not limited herein.

[0148] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.

Claims

1. A method of security evaluation of a receiving station, characterized by, The method comprises the following steps: determining a risk event according to a hazard source in a receiving station to be evaluated, wherein the risk event represents a hazard source out-of-control event; determining a safety index of the receiving station to be evaluated according to historical data of other receiving stations associated with the risk event and a process flow of the receiving station to be evaluated; determining a comprehensive influence matrix according to index scores of the safety indexes, and determining a safety evaluation graph of the receiving station to be evaluated based on the comprehensive influence matrix, wherein the safety evaluation graph is used for searching the risk event of the receiving station to be evaluated, and represents a cause-and-effect relationship and a hierarchy of the safety indexes.

2. The method of claim 1, wherein, The step of determining the safety index of the receiving station to be evaluated according to the historical data of other receiving stations associated with the risk event and the process flow of the receiving station to be evaluated comprises the following steps: identifying causes and prevention barriers of the risk event by fault tree analysis and identifying consequences and mitigation barriers of the risk event by event tree analysis based on the historical data and the process flow; determining a bow-tie model corresponding to the risk event based on the causes, the prevention barriers, the consequences and the mitigation barriers of the risk event; determining the safety index based on the bow-tie model.

3. The method according to claim 1 or 2, characterized in that, The safety index comprises impact factors of the risk event in the personnel dimension, the equipment dimension, the environment dimension and the safety management dimension.

4. The method of claim 1, wherein, The step of determining the comprehensive influence matrix according to the index scores of the safety indexes and determining the safety evaluation graph of the receiving station to be evaluated based on the comprehensive influence matrix comprises the following steps: determining a direct influence matrix according to the index scores of the safety indexes, normalizing the direct influence matrix to determine a normalized influence matrix; performing matrix self-multiplication on the normalized influence matrix to obtain a plurality of candidate influence matrices, and determining the comprehensive influence matrix according to the candidate influence matrices; determining the safety evaluation graph of the receiving station to be evaluated based on the comprehensive influence matrix.

5. The method of claim 4, wherein, The step of determining the safety evaluation graph of the receiving station to be evaluated based on the comprehensive influence matrix comprises the following steps: determining a reachable matrix according to the comprehensive influence matrix, a unit matrix and a preset influence threshold, wherein the reachable matrix represents a reachable relationship between the safety indexes; determining an influence hierarchy of the safety indexes on the risk event and a logical path of the risk event according to the reachable matrix, wherein the influence hierarchy represents an influence degree of the safety indexes on the risk event, and the logical path represents an association structure of the safety indexes; determining the safety evaluation graph of the receiving station to be evaluated according to the influence hierarchy of the safety indexes and the logical path of the risk event.

6. The method of claim 5, wherein, The step of determining the influence hierarchy of the safety indexes on the risk event and the logical path of the risk event according to the reachable matrix comprises the following steps: determining a first index set and a second index set of the safety indexes according to the reachable relationship between the safety indexes in the reachable matrix, wherein the first index set comprises safety indexes having the reachable relationship in the column dimension, and the second index set comprises safety indexes having the reachable relationship in the row dimension. deleting the union set of the first indicator set and the second indicator set from the reachable matrix to obtain a new reachable matrix, and returning to performing determining the first indicator set and the second indicator set of each safety indicator according to the reachable relationship between each safety indicator in the reachable matrix; if the new reachable matrix is empty, determining the influence level of each safety indicator according to the deletion order of the union set; determining the logical path of the risk event according to the reachable relationship between each safety indicator in the reachable matrix.

7. The method of claim 1, wherein, Further comprising: determining the influence degree, the influenced degree, the reason degree and the center degree of each safety indicator according to the comprehensive influence matrix; labeling the influence degree, the influenced degree, the reason degree and the center degree of each safety indicator in the safety evaluation graph.

8. A security assessment device for a receiving station, characterized in that, Comprising: a risk event determination module configured to determine a risk event according to a hazard source in a to-be-evaluated receiving station, wherein the risk event represents a hazard source out-of-control event; a safety indicator determination module configured to determine a safety indicator of the to-be-evaluated receiving station according to historical data associated with the risk event of other receiving stations and a process flow of the to-be-evaluated receiving station; a generation module configured to determine a comprehensive influence matrix according to an indicator score of each safety indicator, and determine a safety evaluation graph of the to-be-evaluated receiving station based on the comprehensive influence matrix, wherein the safety evaluation graph is used for searching the risk event of the to-be-evaluated receiving station, and represents a cause-and-effect relationship and a level of each safety indicator.

9. An electronic device, comprising: The electronic device comprises: at least one processor; and a memory connected with the at least one processor in communication; wherein the memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor to enable the at least one processor to execute the safety evaluation method of the receiving station according to any one of claims 1-7.

10. A computer-readable storage medium, characterized in that, The computer readable storage medium stores computer instructions, and the computer instructions are used to enable the processor to implement the safety evaluation method of the receiving station according to any one of claims 1-7 when executed.

Citation Information

Cited By

  • AI safe operation situation scheduling method and system for LNG receiving station

    CN122414739A